Dear Timeline Security & Risk Analysis

wordpress.org/plugins/deartimeline

A premium, responsive vertical timeline for WordPress. Features a centralized "All-in-One" editor, batch event creation, and custom image di …

0 active installs v1.1.0 PHP 7.2+ WP 5.0+ Updated Apr 14, 2026
historyresponsiveroadmaptimelinevertical-timeline
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Dear Timeline Safe to Use in 2026?

Generally Safe

Score 100/100

Dear Timeline has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The deartimeline plugin v1.1.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The code demonstrates good security practices, notably the complete absence of dangerous functions and file operations, and a commitment to using prepared statements for all SQL queries. A high percentage of outputs are properly escaped, and the presence of both nonce and capability checks on its entry points is commendable, indicating an awareness of common WordPress security vulnerabilities. The absence of any historical CVEs further contributes to a positive security impression.

However, a minor concern arises from the presence of AJAX handlers, even though they are reported as protected. Any form of direct interaction with the application, particularly through AJAX, introduces a potential attack surface that requires vigilant maintenance. While no critical or high-severity taint flows were identified, this is a crucial area to monitor in future analyses as complex logic or updates could inadvertently introduce vulnerabilities.

In conclusion, deartimeline v1.1.0 appears to be a well-secured plugin. Its developers have implemented key security best practices. The limited attack surface and the lack of known vulnerabilities are significant strengths. The primary area to remain attentive to is the ongoing maintenance of its AJAX endpoints to ensure they remain robust against any future threats.

Vulnerabilities
None known

Dear Timeline Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Dear Timeline Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Dear Timeline Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
76 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped80 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<deartimeline> (deartimeline.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Dear Timeline Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_dearti_create_eventdeartimeline.php:464
noprivwp_ajax_dearti_create_eventdeartimeline.php:465

Shortcodes 1

[deartimeline] deartimeline.php:674
WordPress Hooks 9
actioninitdeartimeline.php:100
actionadmin_menudeartimeline.php:115
actionadmin_footerdeartimeline.php:142
actionadd_meta_boxesdeartimeline.php:166
actionsave_postdeartimeline.php:298
actionsave_postdeartimeline.php:319
actionwp_enqueue_scriptsdeartimeline.php:338
actionadmin_enqueue_scriptsdeartimeline.php:372
actionwp_footerdeartimeline.php:744
Maintenance & Trust

Dear Timeline Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 14, 2026
PHP min version7.2
Downloads198

Community Trust

Rating100/100
Number of ratings2
Active installs0
Developer Profile

Dear Timeline Developer Profile

ankit07721

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Dear Timeline

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/deartimeline/assets/css/timeline.css/wp-content/plugins/deartimeline/assets/js/timeline.js
Script Paths
/wp-content/plugins/deartimeline/assets/js/timeline.js
Version Parameters
deartimeline/assets/css/timeline.css?ver=deartimeline/assets/js/timeline.js?ver=

HTML / DOM Fingerprints

CSS Classes
dearti-admin-headerdeartimeline-wrapperdeartimeline-itemdeartimeline-contentdeartimeline-datedeartimeline-year
HTML Comments
<!-- DearTimeline Editor --><!-- Live Desktop Preview --><!-- Timeline --><!-- Dear Timeline -->+1 more
Data Attributes
data-layout
JS Globals
deartimelineData
REST Endpoints
/wp-json/deartimeline/v1/events/wp-json/deartimeline/v1/categories
Shortcode Output
[deartimeline][deartimeline layout="flat"][deartimeline layout="card"][deartimeline layout="classic"]
FAQ

Frequently Asked Questions about Dear Timeline